Risk & Targets
From initial context to explicitly confirmed target security levels.
Risk work in OTReady happens at two different depths, and only one of them produces a target. Keeping them apart is what stops an early orientation exercise from quietly setting the bar the whole assessment is later measured against.
- Initial cyber risk is orientation; it does not produce SL-T
- The detailed IEC 62443-3-2 assessment proposes SL-T
- A proposal becomes a target only when a person confirms it
Two risk layers, doing two different jobs.
Both are real risk work. They differ in depth, in subject, and, decisively, in what they are allowed to conclude.
The wrong reading (initial risk producing SL-T) would let a broad questionnaire set a technical target for a specific conduit it never examined.
Initial cyber risk
Early orientation across broad context: what the entity does, what it would cost if operations stopped, what exposure looks like. Useful for scoping and prioritisation. It does not create a Target Security Level.
IEC 62443-3-2 detailed risk
Scenario-based assessment against zones and conduits, with countermeasures and the residual risk that remains after them. This is the layer that proposes a Target Security Level.
The flow
Nothing skips a step.
- Initial cyber risk
- IEC 62443-3-2 detailed risk
- SL-T proposal
- Explicit confirmation
- Downstream assessment
Requirement filtering downstream uses the CONFIRMED target. An unconfirmed proposal, or a value carried over from an earlier way of working, does not silently take its place.

Detailed risk
Scenario by scenario, against real scopes.
The detailed assessment works over the system under consideration: which scopes and conduits are in scope, what scenarios apply to them, what countermeasures are recorded, and what residual risk is left once those are taken into account.
Because it reasons over canonical architecture rather than an abstract list, its output can name the zone or conduit each conclusion belongs to.
- Risk scenarios recorded against the scopes and conduits they concern
- Countermeasures and the residual risk that remains after them
- A per-subject summary, and a count of proposals still outstanding
Target Security Levels
Seven values are the target. A single number is shorthand.
IEC 62443 expresses a security level as seven foundational requirement values, and that profile is what OTReady treats as authoritative. A single SL label is shown only when a confirmed profile happens to be uniform across all seven; it is a convenience, never the stored truth.
A target is confirmed on a specific admitted subject: a Zone, a Subzone or a Conduit. Admission is its own governance action, so nothing acquires a target simply by existing in the topology.
Once an assessment has been bound to a confirmed target, that binding is what the historical record refers to. Later changes produce a new confirmed version rather than rewriting what an earlier assessment was measured against.
- Proposed and confirmed are two separate states, and a proposal is not a target
- The seven FR values are the authoritative profile
- A scalar label appears only when the confirmed profile is uniform
Unknown is not a number, and SL 0 is not a verdict.
Where no target has been confirmed, OTReady says so. It does not fall back to a default, to a value carried over from an older field, or to zero; an absent target is a fact about the governance process, not a low score. SL 0 can be represented where it is genuinely the confirmed profile, and even then it describes a target, not compliance with anything.
Coming in a later phase
- IEC 62443 standards deep-dive pagesPlanned
- IEC 62443-3-2 methodology pagePlanned
- IEC 62443-3-3 requirements pagePlanned
This page describes how OTReady handles risk and targets. The standards themselves get their own pages later; nothing here is a substitute for reading the norm.
Related capabilities
Architecture
The zones and conduits a target is confirmed against.
Assurance
How confirmed targets feed a derived reading of the project.
IEC 62443-3-2 report
The issued record of the detailed risk process.
See how a target gets set, and by whom.
Walk the path from an initial orientation to a confirmed profile on a real zone or conduit.